4.6 Article

Managing Interdependent Information Security Risks: Cyberinsurance, Managed Security Services, and Risk Pooling Arrangements

期刊

JOURNAL OF MANAGEMENT INFORMATION SYSTEMS
卷 30, 期 1, 页码 123-152

出版社

ROUTLEDGE JOURNALS, TAYLOR & FRANCIS LTD
DOI: 10.2753/MIS0742-1222300104

关键词

cyberinsurance; information security; interdependent risks; managed security services; risk management; risk pooling

资金

  1. National Science Foundation [0831338]
  2. Division Of Computer and Network Systems
  3. Direct For Computer & Info Scie & Enginr [1228990] Funding Source: National Science Foundation
  4. Division Of Computer and Network Systems
  5. Direct For Computer & Info Scie & Enginr [0831338] Funding Source: National Science Foundation

向作者/读者索取更多资源

The interdependency of information security risks often induces firms to invest inefficiently in information technology security management. Cyberinsurance has been proposed as a promising solution to help firms optimize security spending. However, cyberinsurance is ineffective in addressing the investment inefficiency caused by risk interdependency. In this paper, we examine two alternative risk management approaches: risk pooling arrangements (RPAs) and managed security services (MSSs). We show that firms can use an RPA as a complement to cyberinsurance to address the overinvestment issue caused by negative externalities of security investments; however, the adoption of an RPA is not incentive-compatible for firms when the security investments generate positive externalities. We then show that the MSS provider serving multiple firms can internalize the externalities of security investments and mitigate the security investment inefficiency. As a result of risk interdependency, collective outsourcing arises as an equilibrium only when the total number of firms is small.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据